CVE-2026-50601
Last modified
CVE-2026-50601 is a medium-severity vulnerability rated 6.6/10 on the CVSS scale. A security vulnerability has been identified in the Planet9 desktop application where a hardcoded read-only API key permitted unauthorized access to internal repositories. An attacker could exploit this access to extract embedded administrative keys and secrets, potentially allowing them to gain administrative access to repository infrastructure and modify software source code. EPSS estimates a 0.24% chance of exploitation in the next 30 days.
Description
A security vulnerability has been identified in the Planet9 desktop application where a hardcoded read-only API key permitted unauthorized access to internal repositories. An attacker could exploit this access to extract embedded administrative keys and secrets, potentially allowing them to gain administrative access to repository infrastructure and modify software source code. To mitigate this security risk, Acer has released an update to resolve the issue.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Acer | Planet9 desktop application | >= 2.6.131, <= 2.8.124 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-50601?
How severe is CVE-2026-50601?
How do I fix CVE-2026-50601?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-5059aws-mcp-server AWS CLI Command Injection Remote Code Executi…9.8
- CVE-2026-50590In Mimecast Incydr before 2.6.0, arbitrary file access can o…4.5
- CVE-2026-50591In Znuny LTS before 6.5.21 and Znuny before 7.3.3, XSS can o…5.4
- CVE-2026-50592In Znuny LTS before 6.5.21 and Znuny before 7.3.3, there is …6.4
- CVE-2026-50593Graphite before 1.3.15 has an integer underflow and resultan…7.3
- CVE-2026-5060The MasterStudy LMS WordPress Plugin – for Online Courses an…6.5
- CVE-2026-50602A security vulnerability has been identified in Planet9 due …8.5
- CVE-2026-50603A vulnerability has been identified in the Acer Agent Servic…4.9
- CVE-2026-50604A vulnerability has been identified in the Acer Agent Servic…4.9
- CVE-2026-50605A vulnerability has been identified in the Acer Agent Servic…7.4
- CVE-2026-50606A vulnerability has been identified in the Acer System Monit…1.2
- CVE-2026-50607A vulnerability has been identified in the Acer System Monit…2.7
Are you affected by CVE-2026-50601?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
